No federal framework broadly applicable to contractors mandates post-quantum cryptography outright yet, as of September 2026.
CMMC and
FedRAMP both currently rest on cryptography requirements written before PQC standards existed, but a
June 2026 Department of War strategy is already moving to change that for CMMC, with a December 31, 2031 deadline for DoW systems.
What does CMMC require today?
CMMC Level 2 is built on NIST SP 800-171, Revision 2, which includes FIPS-validated cryptography but does not currently prescribe a PQC migration deadline or specific post-quantum algorithms. A June 2026 U.S. Department of War PQC strategy calls for adding PQC to CMMC requirements, with a December 31, 2031 deadline for DoW systems. CMMC’s third-party certification requirement is currently paused pending a Reform Task Force review, the underlying NIST SP 800-171 obligation it’s built on remains in force regardless.
What does FedRAMP require today?
FedRAMP generally requires cryptographic modules validated to FIPS 140 standards. A cloud provider would need FIPS 203 through 205 implemented in FIPS 140-validated modules before deployment, a process that can take years. Some providers are already moving ahead of full validation, for example Cloudflare’s recent FedRAMP High authorization.
How do CMMC and FedRAMP compare on PQC today?
Is CMMC certification currently required?
CMMC’s third-party certification requirement is currently paused pending a Reform Task Force review. The underlying NIST SP 800-171 obligation it’s built on remains in force regardless, so contractors shouldn’t treat the pause as a reason to deprioritize the work.
Why is CMMC's PQC requirement pointed at CMMC and not FedRAMP?
CMMC governs defense contractors handling Controlled Unclassified Information, where the Department of War can set its own timeline. FedRAMP governs cloud service providers to federal civilian agencies and is bound to FIPS 140 module validation, a slower, standards-body process it doesn’t control on its own. That’s why a specific PQC deadline has appeared on the CMMC side first. See the
PQC Compliance Timeline for how this sits alongside CNSA 2.0 and NIST’s release dates.
What should contractors do before federal PQC requirements become mandatory?
Federal contractors don’t need to wait for a hard deadline to start. Understanding which TLS services you operate and what algorithms they negotiate today is the foundation for any future requirement, since federal PQC requirements will likely layer on top of existing frameworks like CMMC’s NIST SP 800-171 baseline rather than replace them. Starting with a baseline assessment now means you’re not scrambling once a specific deadline or customer requirement lands.